Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Global News Feed

POPULAR CYBERSECURITY PUBLICATIONS
2020-10-09 11:56:00 UTC
HackRead
HackRead
Microsoft warns of new Android ransomware blackmailing victims

By Waqas

The AndroidOS/MalLocker.B Android ransomware is also capable of evading detection against several available protections.

This is a post from HackRead.com Read the original post: Microsoft warns of new Android ransomware blackmailing victims

Android Malware Microsoft Security Google Play Store Ransomware Scam
2020-10-09 11:05:00 UTC
The Daily Swig
The Daily Swig
JWT Heartbreaker offers remedy for weak JSON web tokens

Security audits found that 95% of JWT tokens were signed but not encrypted

2020-10-08 21:50:00 UTC
Dark Reading
Dark Reading
Cyberattacks Up, But Companies (Mostly) Succeed in Securing Remote Workforce

Despite fears that the burgeoning population of remote workers would lead to breaches, companies have held their own, a survey of threat analysts finds.

2020-10-08 19:46:00 UTC
ThreatPost
ThreatPost
RAINBOWMIX Apps in Google Play Serve Up Millions of Ad Fraud Victims

Collectively, 240 fraudulent Android apps -- masquerading as retro game emulators -- account for 14 million installs.

Malware Mobile Security Web Security 8-16 Bit Color Palate Ad Fraud Android Emulator Google Play Malicious Ads Malware Nintendo OOC Ads Out Of Context Ads RAINBOWMIX Retro Games White Ops
2020-10-08 19:42:00 UTC
Krebs on Security
Krebs on Security
Amid an Embarrassment of Riches, Ransom Gangs Increasingly Outsource Their Work

There's an old adage in information security: "Every company gets penetration tested, whether or not they pay someone for the pleasure." Many organizations that do hire professionals to test their network security posture unfortunately tend to focus on fixing vulnerabilities hackers could use to break in. But judging from the proliferation of help-wanted ads for offensive pentesters in the cybercrime underground, today's attackers have exactly zero trouble gaining that initial intrusion: The real challenge seems to be hiring enough people to help everyone profit from the access already gained.

A Little Sunshine Ne'er-Do-Well News Web Fraud 2.0 Domaintools Dr. Samuil Intel 471 Mark Arena Sergey Rakityansky
2020-10-08 18:30:00 UTC
HackRead
HackRead
Chowbus food delivery service suffers breach; trove of data stolen

By Deeba Ahmed

The data breach could have affected hundreds of thousands of customers of Fantuan Group Inc. owned Chowbus.

This is a post from HackRead.com Read the original post: Chowbus food delivery service suffers breach; trove of data stolen

Hacking News Breach Chowbus Hacking LEAKS Privacy
2020-10-08 18:00:00 UTC
Dark Reading
Dark Reading
Scale Up Threat Hunting to Skill Up Analysts

Security operation centers need to move beyond the simplicity of good and bad software to having levels of "badness," as well as better defining what is good. Here's why.

2020-10-08 17:55:00 UTC
Dark Reading
Dark Reading
US Seizes Domain Names Used in Iranian Disinformation Campaign

The US has seized 92 domain names used by Iran's Islamic Revolutionary Guard Corps to spread a worldwide disinformation campaign.

2020-10-08 17:30:00 UTC
ThreatPost
ThreatPost
Cisco Fixes High-Severity Webex, Security Camera Flaws

Three high-severity flaws exist in Cisco's Webex video conferencing system, Cisco’s Video Surveillance 8000 Series IP Cameras and Identity Services Engine.

Vulnerabilities Web Security Cisco Cisco Discovery Protocol Cisco WebEx Cisco’s Video Surveillance 8000 Series IP Cameras CVE-2020-3467 CVE-2020-3535 CVE-2020-3544 High Severity Flaw Identity Services Engine Patches Security Camera Security Vulnerabilities
2020-10-08 17:27:00 UTC
ThreatPost
ThreatPost
HEH P2P Botnet Sports Dangerous Wiper Function

The P2P malware is infecting any and all types of endpoints via brute-forcing, with 10 versions targeting desktops, laptops, mobile and IoT devices.

IoT Malware Mobile Security Web Security 360netlab Botnet Brute Forcing Heh Malware Analysis P2P Peer To Peer Self Destruct Telnet Wiper

BreachAware Insight

THE LATEST CURATED INTEL FROM OUR RESEARCH CENTRE

Listen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.

Point of View

OUR TAKE ON TRENDING STORIES
March 2024
By SUE DENIM
TikTok Ban, Discord Bot Community Attack, and Telecom Company's Breach Resurgence.
Ah, the dramatic saga of TikTok in the United States! Picture this: a ban looming over TikTok, akin to a dark cloud threatening to rain on our digital parade. Congress is all up in arms, waving their "think of the children" banners while TikTok nervously checks its watch, wondering if it should start packing its bags for a forced sale. Meanwhile, nobody bats an eye at the plethora of Chinese gadge...

Weekly Summary

SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
22 April 2024
BREACHAWARE HQ

A total of 11 breaches were found and analysed resulting in 8,670,369 leaked accounts containing a total of 26 different data types. The breaches found publicly and freely available included A MONEY, Raychat, Bin Weevils, ZOON and Stealer Log 0450